Results 1 to 5 of 5

Thread: Was DMC Today hacked?

  1. #1

    Was DMC Today hacked?

    Tried to access a google link to an archive (http://www.dmctoday.com/archive/index.php?t-1668.html) and this page comes up as an online pharmacy ad for me. See screenshot below (if I uploaded it correctly)

    Capture.jpg

    Interestingly enough, if I go directly to the link in a new tab, I get the normal archive page as you'd expect, but if I click a link from a google search such as the one below, then I get this pharmacy page every single time. Tested in Chrome and Firefox so it's not something browser specific. All other archive pages that I've tested seem to work normally, but there are probably other issues in the back end that need to be checked out.

    https://www.google.com/search?safe=o...egulator+shims -- second result for me was the link to the dmctoday archive linked above.

    Most likely, the bad guys have inserted some code that looks for a 'referrer' of google or similar and kicks up the rogue page. If it doesn't see Google as the referrer, then it shows the normal page so that it is more stealthy and difficult to find.

    This may be difficult to track down and fix, but I wouldn't trust anything on this site in the meantime. They could have easily compromised the username/password database too so very concerning...

  2. #2
    Mods...
    Bungee Cup Holder Guru

  3. #3
    Uncensored Hypocrite stevedmc's Avatar
    Join Date
    Jul 2013
    Location
    Baton Rouge, LA
    VIN
    16510
    Posts
    5,538
    From what I can tell, it seems to be some sort of Google adsense hack that only targets the AdminCP directory of this forum. I have password protected the AdminCP folder. Any admins that need to get into AdminCP let me know and I will share the password with you.

    This won't affect the use of the forum and from what I've read on the vBulletin support forums, this hasn't compromised any accounts. I will investigate this further as I have time this weekend.
    Rest assured, we have a backup of Farrar's car blog and it will be restored in the near future. (Steve Rice - March 2016)
    Rest assured, we have a backup of Shep's posts and all of them will be restored in the near future. (Steve Rice - March 2017)

  4. #4
    Uncensored Hypocrite stevedmc's Avatar
    Join Date
    Jul 2013
    Location
    Baton Rouge, LA
    VIN
    16510
    Posts
    5,538
    I have sent the AdminCP password to Michael. If any admins need it, reach out to Michael as I am on the road today.
    Rest assured, we have a backup of Farrar's car blog and it will be restored in the near future. (Steve Rice - March 2016)
    Rest assured, we have a backup of Shep's posts and all of them will be restored in the near future. (Steve Rice - March 2017)

  5. #5
    Uncensored Hypocrite stevedmc's Avatar
    Join Date
    Jul 2013
    Location
    Baton Rouge, LA
    VIN
    16510
    Posts
    5,538
    Quote Originally Posted by stevedmc View Post
    I have sent the AdminCP password to Michael. If any admins need it, reach out to Michael as I am on the road today.

    Apparently the same thing happened on that there other forum a couple of years ago.

    http://dmctalk.org/showthread.php?12...ghlight=hacked

    I'm tired and this repair looks a little involved. I tried a few easy fixes that did not resolve it so I may have to install a newer version of vBulletin to fix it. Now I'm seriously wishing I didn't ban Shep.
    Rest assured, we have a backup of Farrar's car blog and it will be restored in the near future. (Steve Rice - March 2016)
    Rest assured, we have a backup of Shep's posts and all of them will be restored in the near future. (Steve Rice - March 2017)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •